App tokens
Generate and manage app tokens to authenticate API requests — with configurable permissions, IP whitelisting, and expiration controls.
An app token is a unique key that allows you to securely interact with the Sumsub API and sign your API calls.
With Sumsub app tokens, you can configure permissions to control which API calls can be made using them. The app tokens enable you to perform various actions such as creating applicants, uploading documents, monitoring verification statuses, and so on through our API.
By default, an app token does not have an expiration period, so it provides unlimited access to the Sumsub API within the permissions set for it — however, you can optionally set an expiration date for a token when generating it, after which it automatically switches to the Expired status.
Generate app token
To generate a token:
- In the Dashboard, open Dev space, go to the App Tokens page, and click Generate app token.
- In the Name field, enter a preferred token name.
- In the Whitelisted IPs section, specify whether this token can be used from any IP address (default), or restrict its usage to specific trusted addresses, which you provide as a comma-separated list.
- [Optionally] From the Source keys from client drop-down list, choose a source key, if you have created it previously. In case there are no available source keys and you want the app token to have access only to a specific group of applicants, refer to this article to learn how to set one up.
- [Optionally] Specify an expiration date for the app token.
- Select permissions by setting corresponding checkboxes according to your preferences. Different permission types allow you to configure how you want to moderate, view, and manage your applicants’ verification or transactions. You can also click Select all to choose all permissions at once.
- Click Generate app token. Consider that once you create an app token, you cannot change the token’s settings.
- Save the token and secret key to a secure location, as they are displayed only once, and confirm it by clicking I’ve saved app token and key securely.
Important
- When an app token is created, Sumsub sends an App token created security email. Each active team member with permission to manage app tokens and access to the corresponding key receives a separate email. The email includes the token name, the client ID of the account the token belongs to, creation time, IP address, and location, so recipients can identify unexpected app token creation.
- To generate an app token that would be valid in Sandbox mode, switch to this mode as explained in this article. You may want to use Sandbox mode in cases where you are testing your integration and do not want to conduct real checks.
- Each token is unique per mode in which it was created; you cannot use an app token in Production mode if this token was created in Sandbox, and vice versa.
- The full-sized app token and secret key values are shown in the Dashboard only once — at the moment you create the token; make sure to save it to a secure location.
- IP restriction rules applied to your role do not limit token creation. For example, you can create a token without IP restrictions, even if your role has IP limitations.
View app tokens
Open the Dev space → App Tokens section to view information about all tokens created on your key, including their name, status, created date, and usage count. The Usage column shows the number of requests made using each token over the last 30 days.
To find a specific token, use the search field or narrow down the results using the following filters:
- Permissions — filters tokens by the permissions assigned to them.
- Status — filters tokens by their current status: Enabled, Disabled, or Expired.
- Author — filters tokens by the user who created them.
- Source key — filters tokens by the source key they are associated with.
You can also click the filter icon next to the Created column heading to sort tokens by creation date.
Click a token in the list to expand additional details, including its Permissions, Whitelisted IPs, and Source keys sections.
Manage app tokens
You can manage app tokens by clicking the three-dot menu next to the corresponding token and selecting the following options:
- Enable or disable a token. When disabling a token, you will be prompted to specify a reason.
- Delete a token.
Note
- To view this reason a token was disabled, click the dialog icon next to the token status — a popover displays the reason and the date when the token was disabled.
- A disabled token cannot be used for API requests. Re-enabling the token restores its access.
- Expired tokens cannot be enabled or disabled.
Updated 5 days ago